US9805186B2ActiveUtilityA1

Hardware protection for encrypted strings and protection of security parameters

Assignee: ADOBE SYSTEMS INCPriority: Feb 26, 2008Filed: Mar 3, 2015Granted: Oct 31, 2017
Est. expiryFeb 26, 2028(~1.6 yrs left)· nominal 20-yr term from priority
Inventors:David A. Pohm
G06F 21/602G06F 21/44H04L 9/06G06F 21/78
72
PatentIndex Score
2
Cited by
15
References
14
Claims

Abstract

In one embodiment, a disk drive is provided that is adapted for security authentication. The disk drive includes: a non-volatile memory storing object code; a processor for retrieving the stored object code; a decryption engine for decrypting a retrieved shared secret from the object code; and a first memory for storing the decrypted retrieved shared secret; wherein the processor is configured to overwrite the written decrypted retrieved shared secret after it has been used in an authentication procedure.

Claims

exact text as granted — not AI-modified
The invention claimed is: 
     
       1. A data drive adapted for security authentication, the data drive comprising:
 a non-volatile memory storing object code for booting a first computing device; 
 a processor configured for retrieving a shared secret from the stored object code; 
 a decryption engine for decrypting the shared secret retrieved from the object code; and 
 a memory for storing the decrypted retrieved shared secret; 
 wherein the processor is further configured for (i) proving possession of the decrypted shared secret to a second computing device that is external to the first computing device and (ii) overwriting the written decrypted retrieved shared secret after proving the possession of the decrypted shared secret to the second computing device and thereby proving the first computing device to be a trusted party. 
 
     
     
       2. The data drive of  claim 1 , wherein the non-volatile memory is a FLASH memory. 
     
     
       3. The data drive of  claim 1 , wherein the non-volatile memory is a ROM memory. 
     
     
       4. The data drive of  claim 1 , wherein the memory for storing the decrypted retrieved shared secret is the non-volatile memory. 
     
     
       5. The data drive of  claim 1 , wherein the memory for storing the decrypted retrieved shared secret is a volatile memory. 
     
     
       6. The data drive of  claim 1 , wherein the decryption engine is a linear feedback shift register (LFSR). 
     
     
       7. The data drive of  claim 1 , wherein the decryption engine is the processor. 
     
     
       8. A method comprising:
 retrieving, by a processor and from a non-volatile memory of a disk drive, object code for booting a first computing device, the object code containing an encrypted secret; 
 retrieving, by the processor, the encrypted secret from the object code; 
 decrypting, by the processor executing a decryption engine stored within the disk drive, the encrypted secret retrieved from the object code; 
 writing the decrypted retrieved secret to a memory; 
 proving, by the processor, possession of the decrypted secret to a second computing device that is external to the first computing device; and 
 writing over the decrypted secret and thereby erasing the decrypted secret from the memory after proving the possession of the decrypted secret to the second computing device and thereby proving the first computing device to be a trusted party. 
 
     
     
       9. The method of  claim 8 , wherein the memory to which the decrypted secret is written is the non-volatile memory. 
     
     
       10. The method of  claim 8 , wherein the non-volatile memory is a FLASH memory. 
     
     
       11. The method of  claim 8 , wherein the non-volatile memory is a ROM memory. 
     
     
       12. The method of  claim 8 , wherein the non-volatile memory is an optical disk. 
     
     
       13. The method of  claim 8 , wherein the non-volatile memory is a magnetic hard disk drive. 
     
     
       14. The method of  claim 8 , wherein the non-volatile memory is a disk drive.

Join the waitlist — get patent alerts

Track US9805186B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.